{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90324","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.802Z","datePublished":"2026-09-17T16:08:40.077Z","dateUpdated":"2026-09-18T17:54:36.580Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:54:36.580Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nublk: check import_ubuf() return value\n\nimport_ubuf() can fail if the address range (provided by the userspace\nublk server) is outside the allowed user address space. Return that 0\nbytes were copied if import_ubuf() fails rather than passing an\nuninitialized struct iov_iter to ublk_copy_user_pages()."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bad pointer is io->buf.addr from ublksrv_io_cmd.addr in ublk_ch_uring_cmd_local() on UBLK_IO_FETCH_REQ, UBLK_IO_COMMIT_AND_FETCH_REQ, or UBLK_IO_NEED_GET_DATA against /dev/ublkcN. import_ubuf() in ublk_map_io()/ublk_unmap_io() is handed that local userspace address; no network protocol carries it.\nAC:L - The ublk server chooses the FETCH/COMMIT buffer address. A non-zero kernel or wrap-around address fails access_ok() in import_ubuf() on every call (ublk_check_fetch_buf() only rejects addr==0). ublk_map_io()/ublk_unmap_io() then pass the uninitialized iov_iter to ublk_copy_user_pages() with no race or victim state.\nPR:L - ublk_ctrl_add_dev() lets a caller without CAP_SYS_ADMIN create a UBLK_F_UNPRIVILEGED_DEV device, and those devices cannot set UBLK_F_USER_COPY, UBLK_F_SUPPORT_ZERO_COPY, or UBLK_F_AUTO_BUF_REG, so ublk_need_map_io() is always true. ublk_ch_open() has no capability check; ublk_open() allows the owner to issue I/O to /dev/ublkbN.\nUI:N - The attacking process itself issues UBLK_CMD_ADD_DEV and UBLK_CMD_START_DEV on /dev/ublk-control, UBLK_IO_FETCH_REQ with the bad addr on /dev/ublkcN, then read/write on its own ublkb disk so ublk_queue_rq() → ublk_cmd_tw_cb() → ublk_dispatch_req() runs. No other user must mount or open anything.\nS:U - ublk_copy_user_pages() copies between the ublk request bio pages and the confused iov_iter entirely inside the host kernel via _copy_to_iter()/_copy_from_iter(). This is local kernel memory corruption, not a VM, IOMMU, or hypervisor escape.\nC:H - On a READ, ublk_unmap_io() calls _copy_from_iter() with the uninitialized iov_iter. iterate_and_advance() may treat leftover iter_type as ITER_KVEC or ITER_BVEC, so memcpy_from_iter() copies kernel memory into the request bio pages, which the attacker then reads from /dev/ublkbN.\nI:H - On a WRITE, ublk_map_io() calls _copy_to_iter() with that uninitialized iter, so iterate_kvec()/memcpy_to_iter() can write the attacker-controlled ublkb write payload to leftover kernel pointers. Garbage iter_type is iov_iter type confusion and an arbitrary kernel write.\nA:H - iterate_kvec() loads p->iov_len from leftover kvec pointers and iterate_bvec() calls kmap_local_page() on leftover bv_page, either of which oopses. ublk_unmap_io() also hits WARN_ON_ONCE(!data_source) in _copy_from_iter() when the iter was left with data_source==0."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/block/ublk_drv.c"],"versions":[{"version":"981f95a571e3ca20a496c0b77dbf6b06039c6648","lessThan":"0121c84adb6a4cd6f7560b5895bd88f9899bbc1f","status":"affected","versionType":"git"},{"version":"981f95a571e3ca20a496c0b77dbf6b06039c6648","lessThan":"5ac6019cb78e98c9608fda72726b36ddf8474dd7","status":"affected","versionType":"git"},{"version":"981f95a571e3ca20a496c0b77dbf6b06039c6648","lessThan":"3831568792af75b6523fa93bb91560e29189cf55","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/block/ublk_drv.c"],"versions":[{"version":"6.5","status":"affected"},{"version":"0","lessThan":"6.5","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.5","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.5","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.5","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/0121c84adb6a4cd6f7560b5895bd88f9899bbc1f"},{"url":"https://git.kernel.org/stable/c/5ac6019cb78e98c9608fda72726b36ddf8474dd7"},{"url":"https://git.kernel.org/stable/c/3831568792af75b6523fa93bb91560e29189cf55"}],"title":"ublk: check import_ubuf() return value","x_generator":{"engine":"bippy-1.2.0"}}}}